CVEFeed Newsroom – Latest Cybersecurity Updates
The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 10 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.
-
The Cyber Express
SonicWall Warns of Two Actively Exploited SMA1000 Zero-Days, One Rated Maximum Severity
SonicWall disclosed this week that attackers are chaining two previously unknown vulnerabilities in its SMA1000 secure access appliances to run commands on unpatched devices, and urged customers to in ...
-
The Hacker News
Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a privilege escalation flaw impacting Crowd ...
-
The Hacker News
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers' crosshairs ...
-
TheCyberThrone
CISA Adds 7 Vulnerabilities to KEV: A New Wave of Actively Exploited Flaws
On September 2, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added seven vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, marking another reminder that ...
-
The Hacker News
Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's mac ...
-
The Hacker News
Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks. The vulnerabilit ...
-
security.nl
Tweehonderd PaperCut NG/MF-servers missen update voor aangevallen lek
Meer dan tweehonderd PaperCut NG/MF-servers, waaronder zeven in Nederland, missen een belangrijke beveiligingsupdate voor twee kwetsbaarheden waar aanvallers actief misbruik van maken. Via de beveilig ...
-
The Hacker News
GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends
Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geo ...
-
security.nl
Google dicht Chrome-lekken die remote code execution mogelijk maken
Google heeft beveiligingsupdates uitgebracht voor kritieke kwetsbaarheden in Chrome die remote code execution mogelijk maken. Een aanvaller kan zo code op de systemen van gebruikers uitvoeren, waarbij ...
-
The Hacker News
Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another
Forescout Research - Vedere Labs said it used Anthropic's Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, ...